Windows Server 2016 end of life arrives on January 12, 2027. That day, Microsoft ships the last regular security update for a system that still runs file shares, domain controllers, and business databases in offices that bought their servers in 2017 or 2018. The server will not shut off that morning. It will keep working exactly as it does today, and that is the problem: every weakness found after that date stays open, with nothing on screen to warn you.
Microsoft 365 and HIPAA: What the BAA Covers and What You Configure

For a business owner, this is not really a technical decision. It is a set of questions about money, timing, and risk: which machines are affected, whether extra updates from Microsoft are worth paying for, which version to move to, and whether you can finish before the holidays. This guide answers each question in order, using Microsoft's published dates and requirements, so you can decide with your IT provider instead of hearing about it from an auditor.
What Windows Server 2016 End of Life Means on January 12, 2027
Microsoft supports Windows Server under its Fixed Lifecycle Policy: a period of mainstream support, followed by extended support that delivers security updates only. For Windows Server 2016, mainstream support ended on January 11, 2022. Extended support ends on January 12, 2027, for the Standard, Datacenter, and Essentials editions alike. After that date, Microsoft stops releasing security and bug fixes and ends assisted support.
Windows Server 2016 end of support, often called EOL or end of life, does not stop the server itself. Files still open, logins still work, and the accounting database still answers queries. That is exactly why these deadlines get missed: the risk stays invisible until someone uses it.

Why an Unpatched Server Becomes a Target
Microsoft keeps publishing monthly security fixes for Windows Server 2019, 2022, and 2025. Many flaws sit in code those versions share with 2016. Each month's fixes can therefore point attackers to a weakness that stays open on every 2016 machine that never receives the patch. An old server that holds the keys to the domain is worth more to them than any single laptop.
The exposure also grows over time. Unless the server is enrolled in paid extended updates, your patch management process has nothing left to deploy to it. Meanwhile, vendors of endpoint protection, backup, and remote management tools tend to drop support for retired systems, so the server loses its protective layers as well as its patches.
Other 2016-Era Products on the Same Clock
Windows Server 2016 rarely retires alone. SQL Server 2016, the database engine behind many line-of-business applications, left support on July 14, 2026. Exchange Server 2016 lost support in October 2025. If your 2016 server also hosts one of these, the plan must cover both layers, because a new operating system under an unsupported database solves only half the problem.
Offices that went through the Windows 10 deadline in October 2025 will recognize the pattern. The difference is scale. A retired laptop affects one desk, while a retired server can take down sign-ins, shared files, and the practice or accounting system for everyone at once.
Find Every Windows Server 2016 Machine Before You Plan
The server in the closet is often not the only one. Once someone looks, Windows Server 2016 tends to turn up in several places, including virtual machines nobody thinks of as separate servers. Check these first:
- Domain controllers that handle sign-ins, DNS, and group policy for the office.
- File servers behind the mapped drives everyone uses.
- Remote Desktop servers that host shared desktops and applications.
- Database servers behind practice management, accounting, ERP, or case management software.
- Hyper-V hosts, where the host itself may run 2016 even if its virtual machines are newer.
- Vendor-installed systems for phones, cameras, door access, or imaging equipment, which sometimes run Windows Server underneath.
- Backup servers and the machine that runs your backup console.
To check a single machine, run winver or open Settings. Windows Server 2016 reports itself as version 1607, OS build 14393. Your IT provider's monitoring platform should produce the full list in minutes, including physical hosts, virtual machines, and anything a vendor installed and never handed over.

Map the Applications Before the Operating System
For each server, write down what runs on it and who supports that software. Then check each vendor's current system requirements for Windows Server 2025. A practice management or accounting vendor that only certifies older versions will shape your timeline more than Microsoft will, so this list decides which servers can move quickly and which need a vendor conversation first.
Extended Security Updates: A Paid Bridge With Conditions
In February 2026, Microsoft announced Extended Security Updates (ESUs) for Windows Server 2016. ESUs deliver Critical and Important security updates for up to three years after end of support, through January 2030. They include nothing else: no new features and no non-security fixes. Delivery runs through Azure Arc, Microsoft's service for managing on-premises servers from the Azure portal.
The billing rules are strict. Billing starts on January 13, 2027, and servers enrolled later are back-billed to January 12, 2027. Waiting to see whether you need the updates does not save money.
The Requirements That Rule Out Many Small Offices
Microsoft's ESU documentation sets conditions that matter more to small businesses than price. For servers running on premises, you need Software Assurance through a volume licensing program, or an equivalent Windows Server subscription. Many small offices bought Windows Server bundled with the hardware and never had Software Assurance. For them, extended updates may not be available without changing how the server is licensed.
There are other gates. Microsoft lists support for the Standard and Datacenter editions, so an office on the Essentials edition should confirm eligibility first. Each server also needs the Azure Connected Machine agent and outbound access to Microsoft's endpoints. Licensing by physical cores carries a minimum of 16 cores per machine.
When Paying for the Bridge Makes Sense
ESUs make sense for a specific server with a specific reason to wait. Examples include an application whose vendor has not certified Windows Server 2025, or a hardware replacement already scheduled for early next year. They are a poor substitute for a plan, because the updates cover security flaws while everything around the server keeps aging. Treat an ESU enrollment as a dated exception with an exit date, not as permission to run 2016 until 2030.
Choosing the Next Version: Why Windows Server 2025 Usually Wins
Moving to the next release up is not automatically the safest choice. Windows Server 2019 is already in extended support, and its security updates end on January 9, 2029. A 2019 upgrade therefore buys about two years before the same project starts again. Windows Server 2022 has a mainstream support end date of October 13, 2026, so a server built on 2022 now spends almost its whole service life in the maintenance phase.
Windows Server 2025 is the version that avoids a second migration within a few years. Here is how the support dates line up:
- Windows Server 2016: security updates through January 12, 2027.
- Windows Server 2019: security updates through January 9, 2029.
- Windows Server 2022: mainstream support through October 13, 2026, and security updates through October 14, 2031.
- Windows Server 2025: mainstream support through November 13, 2029, and security updates through November 14, 2034.
The Remote Desktop Catch
If staff run Office on a shared Remote Desktop server, the version choice matters even more. For Windows Server 2022 and 2025, Microsoft supports Microsoft 365 Apps only while that server version is in mainstream support. Support on Windows Server 2016 already ended in October 2025. For 2022, support ends in October 2026, while 2025 is covered through October 2029.
A terminal server upgraded to 2022 now would get little or no Office support for the rest of its life. For shared desktops, the realistic choices are Windows Server 2025 or moving those desktops to a cloud service such as Windows 365 or Azure Virtual Desktop.
Compatibility Checks Before You Commit
Windows Server 2025 changes a few defaults that can surprise an older office. It requires signed file-sharing connections, known as SMB signing, whenever it connects to other devices. Mapped drives on an older network storage box that cannot sign, or that relies on guest access, can stop working until the device is updated. Older RAID controllers and network cards may also lack drivers for the new version, so confirm support before booking a weekend for the cutover.
Licensing needs its own line in the budget. Windows Server is licensed per core, and client access licenses must match or exceed the server's version. Access licenses bought for 2016 therefore do not cover a 2025 server, and the same rule applies to Remote Desktop licenses on terminal servers.
Four Ways Forward, and How to Choose Yours
Every 2016 server ends up on one of four paths. The right one depends on the age of the hardware, what the server does, and how much downtime the business can absorb. If you are still deciding whether to replace the server or move it to the cloud, settle that question first, because it changes which paths are on the table.

Upgrade in Place
Microsoft supports an in-place upgrade from Windows Server 2016 directly to 2019, 2022, or 2025, as long as you keep the same edition. It suits a simple server on healthy hardware, such as a file server that is only a few years old. The trade-off is that years of old settings and leftovers come along too. A verified image backup and a tested rollback plan are not optional.
Replace the Hardware and Migrate
A server bought while 2016 was the current release is now roughly eight to ten years old. Hardware of that age is a reliability risk in its own right. Building a new server on Windows Server 2025 and moving roles, data, and applications across gives you a clean system. It also gives you a fallback, because the old machine stays untouched until the new one is proven.
Timing can help the budget. Equipment purchased and placed in service before December 31 may qualify for the Section 179 deduction on this year's return. A replacement ordered in the next few weeks can therefore do double duty, although your tax advisor should confirm how the rules apply to your business.
Move the Workload to the Cloud
Some server roles no longer need a server at all. Shared files often fit better in SharePoint and OneDrive. For many small offices, sign-in and device management can move to Microsoft Entra ID and Intune, with no domain controller in the closet.
Applications are the harder part. A line-of-business application that still needs Windows Server can run as a virtual machine on managed cloud infrastructure instead of a box in the office. That also ends the hardware replacement cycle for that workload.
Retire It
Some 2016 servers exist for a job the business stopped doing years ago. Examples include an old accounting system kept for lookups, or a print server for printers that are long gone. Retiring them is the cheapest path, as long as any data you must keep is first exported to a supported, searchable location. Then remove the machine from the domain and wipe the drives properly before it leaves the building.
In practice, many businesses combine paths. A common result is a new domain controller on Windows Server 2025 and shared files in SharePoint. One legacy application often stays on premises in a hybrid cloud design while its vendor catches up.
What an Unsupported Server Means for HIPAA, PCI, and Insurance
Compliance rules rarely name an operating system, but they do require you to manage known risks. The HIPAA Security Rule requires risk analysis and risk management for systems holding electronic protected health information. A server that no longer receives security fixes is exactly the kind of risk that analysis must document and address. Keeping one past the deadline without a documented reason and compensating controls is hard to defend if something goes wrong.
Payment card rules are more explicit. Requirement 12.3.4 of PCI DSS 4.0.1, the current version of the standard, has been mandatory since March 31, 2025. It requires businesses in scope to review their hardware and software at least every 12 months, document vendor end-of-life announcements, and keep a management-approved plan to replace outdated technology.
Cyber insurance adds a practical test. Before your next renewal, check the application and the policy for questions or exclusions about unsupported systems. An inaccurate answer can cause trouble at claim time, so the honest answer next year depends on the work you finish this quarter.
A Timeline for the Weeks Left
By the time many offices start planning, the calendar is shorter than it looks. The holidays alone take two or three weeks out of it. A realistic schedule looks like this:
- Right away: finish the inventory and the application list, confirm vendor support for Windows Server 2025, and choose a path for each server.
- As soon as the paths are set: order hardware and licenses, since server and memory lead times can stretch without warning.
- The weeks before the holidays: build, migrate in stages, and test a restore before each cutover.
- Late December: freeze changes over the holidays and keep the old servers available as a fallback.
- By January 12: retire, disconnect, or enroll in ESUs every remaining 2016 machine, and record the decision for each one.
A schedule like this is what a technology planning engagement should produce: dates, owners, and a decision for each machine. It also gives you something concrete to show an auditor or an insurer if they ask.
If a server cannot make the date, reduce what it can reach and what can reach it. Move it to its own network segment, block its direct internet access, limit who can sign in, and monitor it closely until the replacement is ready.
The Cost of Waiting Past January
The cheapest version of this project is the planned one. Migrations squeezed into early January cost more in overtime, rushed hardware, and mistakes. A breach that starts on an unpatched server can cost more than all of those combined. Windows Server 2016 end of life is a fixed date, which makes it one of the few IT risks you can see coming months in advance.
Businesses that start now get to choose their weekends, their hardware, and their version. For offices that want local help, managed IT services in Los Angeles can cover the inventory, the migration, and the follow-up as one plan instead of a string of emergencies.
Frequently Asked Questions
If you are not sure which servers are affected or which path fits each one, GlobeVM can review your Windows Server 2016 end of life plan with you and map the steps to January.
Comments
0 Comments